Open
Description
Describe the bug
The security policy https://github.com/NixOS/nix/security/policy requires reporting to the NixOS security team, but that indirection seems (EDIT: seemed to me) unnecessary and counterproductive, as it is important to work towards a patch ASAP.
I understand that @NixOS/security may want to be involved. Could we change the process so that the Nix team gets in touch with the security team instead? I believe their involvement is most relevant towards the end of the process.
Additional context
Priorities
Add 👍 to issues you find important.